Cash machines infected with malicious USB sticks

Hacker
An inside job? Surely bankers have enough money

Criminals have targeted cash machines, a report says, by cutting hole in the fascia to infect the machine with malicious code via USB sticks. The infected ATMs were then able to spit out notes on command.

Speakers at the hacker-themed Chaos Computing Congress in Hamburg described the attacks, which infected an unnamed European bank that noticed several cash machines were emptied entirely without the safe being damaged.

The bank in question increased security after the first attacks and were able to spot the gang drilling holes in the front of the machines before inserting a USB flash drive. Once the malware had been transferred they patched the holes up. This allowed the same machines to be targeted several times without the hack being discovered.

Profound knowledge

The gang would then return at a later date and instruct the compromised machine to dispense a specific amount of cash. They used a 12 digit code, followed by what was believed to be a failsafe to prevent individuals in the group from stealing money themselves. The correct response varied each time and the thief could only obtain the right code by phoning another gang member and telling them the numbers displayed.

Researchers, who asked not to be named, found that the software then showed how many of each denomination of banknote were in the machine, and asked how much of each it should dispense. This enabled the attackers to focus on the highest value banknotes and minimise their exposure.

They said that the gang must have had a "profound knowledge" of the workings of cash machines in order to develop and successfully install the software in such an efficient manner. However, they added that the approach did not extend to the software's filenames - the key one was called 'hack.bat'.

Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 16 (game #1147)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 16 (game #378)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 16 (game #644)
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before